6 ms·
Recently transitioned from Ubiquit stuff to a OPNSense setup. It was such a good decision. The firewall rules make much more sense. Better functions than the dr
by syntaxing 3y ago
Recently transitioned from Ubiquit stuff to a OPNSense setup. It was such a good decision. The firewall rules make much more sense. Better functions than the dream machine series. You can also get a lot more for the same price. Ubiquti hardware is very under spec for the money you pay for. Highly recommend this guide to setup your own. It’s very dense and more verbose than you need so skip the irrelevant sections.
[1] https://homenetworkguy.com/how-to/set-up-a-fully-functioning-home-network-using-opnsense/ https://homenetworkguy.com/how-to/set-up-a-fully-functioning...
- philsnow 3y agoI’ve been thinking about swapping out my UDMP for opnsense, but keeping the ubiquiti APs, they’re the best I’ve ever known and I think they play reasonably well with non-ubiquiti stuff. Thanks for the link to the guide!
- syntaxing 3y agoYou can actually run the controller with a plugin too! Worked great, didn’t have any issues when I was still using my ubiquiti switches and AP.
- nvy 3y agoI've been looking at this as well. I'm currently running my gigabit fiber connection through a GPON-ethernet media converter and from there over Cat 6 to a ubiquiti Edgerouter-X. It does okay with hardware offloading enabled for things like ipsec and NAT, but it's taxing the CPU and I'd like to move to something with a little more headroom. Got any recommendations for something that can route beyond gigabit, when NATing and DPIing and other things?
- abwizz 3y ago> Got any recommendations for something that can route beyond gigabit, when NATing and DPIing and other things? goto recommendation for the last decade is a used small formfactor enterprise desktop or a laptop. the former allows for a pcie nic and more performance while the latter usually requires a usb-eth but has a builtin keyboard and screen for debugging. just go for something x86, avoid the ultra low-end cpu's and your usually good for soho stuff.
- syntaxing 3y agoYou should checkout the new R862 mini pcs. You can get 3X 2.5 NIC and 2 SFP port with 10G support. The homenetworkguy did a great review on it. But overall, 10G works but only with nothing turned on. With IPS/IDS and proper MTU, you can get about 3 Gbps. But all this for sub $400 in a computer about the size of your hand is insane to me.
- btobolaski 3y agoI think you mean R86S, I wasn’t able to find something relevant by R862. They’re pretty interesting. I am sort of looking to replace my R210ii and this fits the bill but downgrading cpu performance (for a great deal of efficiency gain) kind of feels bad.
- syntaxing 3y agoAha yeah, I’m on mobile so it was a typo. I currently run a fanless mini pc with N100 and 4X 2.5G which has been great. If you don’t need SFP and can live with LAGG + 2.5G, you can probably get pretty similar real world speeds compared to a 10G SFP line.
- alias_neo 3y agoI switched to pfSense from EdgeRouter a few years back, and find the firewall rules make _less_ sense. The reason is likely that I understand IPTables pretty well, where as the approach used in pfSense seems "abstract" in comparison. I'd certainly recommend grabbing something like a Protectli box (if power draw is a concern) or building a small server with NICs to install OPNSense on over the Ubiquiti stuff. For me, the router graveyard was getting out of hand, buying everything from mid-range to high-end consumer routers only to have them left behind software-security wise within 3 years, I needed something open. The promise of the EdgeRouter range was the hardware offload and Debian based OS, but Ubiquiti has fallen out of favour with me in that space, their software has gotten worse rather than better over time. I went with Protectli because of the ability to use Coreboot meaning I could get as much of the stack Open Source as possible. Unfortunately, at the time I set it up, OPNSense didn't work for my requirements and I had to use pfSense; pfSense is now too falling out of favour, but I don't have the time to swap over a fairly large home network without pissing off the family.
- ThatMedicIsASpy 3y agoI recently switched to RouterOS. The learning curve was a bit high to me. I'm still tinkering with it but I got my main things working - vlans, default internet access out via vpn, one port (internet accessible server) routed without vpn. I learned a lot in the last 3 weeks it also helped me understand networking a lot more. Sure I had to do a lot of trial and error or figure out why things don't work but in the end it was worth it for me. I came from 30€ OpenWRT routers with only 100mbit links which is why I upgraded. The hAP ax³ were 140€ a piece (I use two) and the one 2.5Gb PoE port is actually nice since it powers the second router. It was a pricey upgrade compared to what was there before. I tried to buy another OpenWRT router but RouterOS seems to offer 10 times more compared to what OpenWRT can do. I've looked at a lot of things even one of the more looked at super cheap thin client for this stuff (Fujitsu Futro S920). At home I can't really justify a dedicated firewall.
- sgt 3y agoRouterOS has a steeper learning curve, but I find it very comforting that it is predictable/boring and I run it on hardware that is easily replacable. I have a cheap Mikrotik 1U unit.
- buro9 3y agoHow does the link aggregation work? I get that OPNSense can do this, but do you need a switch with a capability to make sense of this? I'm considering moving from Unifi USG to OPNSense and have two Cat6a runs from one end of the house to the other (through the loft and it's not possible to add more runs without building/decorating work). Presently the two cables do WAN and LAN, but I've been curious about putting something closer to the modem and to somehow use both cables for the LAN. LAGG looks like it can do this and isn't something I knew about for the home. Would I need a special switch on the other end? I've currently got Ubiquiti switches but as I'm already looking at binning the USG I'm fairly open to reconsidering a lot of the network. PS: The reason to abandon the USG is heat issues. Packet loss when the ambient room temperature exceeds 30'c, and serious packet loss when the room temp is 35'c. This is no longer rare, and the USG is only rated to ambient temp of 40'c and there are many Reddit threads of people ripping the case apart and fitting fans. I'd rather just have stable internet with better hardware.
- vladvasiliu 3y agoI think there are multiple ways to set up a lagg, but the one I've tried and works fine is LACP. This requires an equipment that can handle this at the other end, though. I'm not familiar with Ubiquiti kit, so you'd have to check if it's supported.
- abwizz 3y agoif you want to have two links grouped together so that a single transfer uses both links together (2gbps) then the switch has to support it. default is for two separate transfers to each get one gbit, which is good enough for most applications. packet loss at summer temps is indicative of faulty hardware (maybe just the thermal paste or other parts of the heat management)
- buro9 3y ago> packet loss at summer temps is indicative of faulty hardware (maybe just the thermal paste or other parts of the heat management) there is no heat management in the Ubnt USG. no thermal paste on the hot network ports, no cooling design beyond passive cooling (little air holes in the side of the case) that doesn't work when it's laid flat (need to vertically mount to encourage airflow). most of the hacks are people fitting fans in a case that isn't designed for it: i.e. https://old.reddit.com/r/Ubiquiti/comments/cr88fw/cooling_the_new_usg_3p_with_a_diy_solution_the/ https://old.reddit.com/r/Ubiquiti/comments/cr88fw/cooling_th... if the USG is in a cupboard or somewhere with poor airflow, and it's the Summer, then it's packet loss city. would agree that this is a faulty hardware, faulty by design.